{"id":28541181,"url":"https://github.com/fkemser/scwrapper","last_synced_at":"2026-07-04T22:31:32.356Z","repository":{"id":297681022,"uuid":"763205508","full_name":"fkemser/SCwrapper","owner":"fkemser","description":"A collection of shell scripts to interactively initialize and manage certain smartcards, USB tokens, and hardware security modules (HSMs).","archived":false,"fork":false,"pushed_at":"2025-07-31T21:36:49.000Z","size":15230,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-10-27T05:16:06.232Z","etag":null,"topics":["hsm","opensc","piv","pkcs11","pkcs15","security","smartcard","yubico","yubikey"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fkemser.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2024-02-25T20:23:52.000Z","updated_at":"2025-07-31T21:36:53.000Z","dependencies_parsed_at":"2025-08-07T15:30:54.377Z","dependency_job_id":null,"html_url":"https://github.com/fkemser/SCwrapper","commit_stats":null,"previous_names":["fkemser/scwrapper"],"tags_count":0,"template":false,"template_full_name":"fkemser/SHtemplate","purl":"pkg:github/fkemser/SCwrapper","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkemser%2FSCwrapper","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkemser%2FSCwrapper/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkemser%2FSCwrapper/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkemser%2FSCwrapper/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fkemser","download_url":"https://codeload.github.com/fkemser/SCwrapper/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fkemser%2FSCwrapper/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35138074,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-04T02:00:05.987Z","response_time":113,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["hsm","opensc","piv","pkcs11","pkcs15","security","smartcard","yubico","yubikey"],"created_at":"2025-06-09T19:38:21.056Z","updated_at":"2026-07-04T22:31:32.327Z","avatar_url":"https://github.com/fkemser.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003c!-- Improved compatibility of back to top link: See: https://github.com/othneildrew/Best-README-Template/pull/73 --\u003e\n\u003ca name=\"readme-top\"\u003e\u003c/a\u003e\n\u003c!--\n*** Thanks for checking out the Best-README-Template. If you have a suggestion\n*** that would make this better, please fork the repo and create a pull request\n*** or simply open an issue with the tag \"enhancement\".\n*** Don't forget to give the project a star!\n*** Thanks again! Now go create something AMAZING! :D\n--\u003e\n\n\n\n\u003c!-- PROJECT SHIELDS --\u003e\n\u003c!--\n*** I'm using markdown \"reference style\" links for readability.\n*** Reference links are enclosed in brackets [ ] instead of parentheses ( ).\n*** See the bottom of this document for the declaration of the reference variables\n*** for contributors-url, forks-url, etc. This is an optional, concise syntax you may use.\n*** https://www.markdownguide.org/basic-syntax/#reference-style-links\n--\u003e\n[![Contributors][contributors-shield]][contributors-url]\n[![Forks][forks-shield]][forks-url]\n[![Stargazers][stars-shield]][stars-url]\n[![Issues][issues-shield]][issues-url]\n[![GNU GPL v3.0 License][license-shield]][license-url]\n\u003c!-- [![LinkedIn][linkedin-shield]][linkedin-url] --\u003e\n\n\n\n\u003c!-- PROJECT LOGO --\u003e\n\u003cbr /\u003e\n\u003cdiv align=\"center\"\u003e\n  \u003c!-- \u003ca href=\"https://github.com/fkemser/SCwrapper\"\u003e\n    \u003cimg src=\"images/logo.png\" alt=\"Logo\" width=\"80\" height=\"80\"\u003e\n  \u003c/a\u003e --\u003e\n\n\u003ch3 align=\"center\"\u003eSCwrapper\u003c/h3\u003e\n\n  \u003cp align=\"center\"\u003e\n    A collection of shell scripts to initialize and manage certain smartcards, USB tokens, and hardware security modules (HSMs), either interactively or via command line.\n    \u003cbr /\u003e\n    \u003ca href=\"https://github.com/fkemser/SCwrapper\"\u003e\u003cstrong\u003eExplore the docs »\u003c/strong\u003e\u003c/a\u003e\n    \u003cbr /\u003e\n    \u003cbr /\u003e\n    \u003ca href=\"https://github.com/fkemser/SCwrapper\"\u003eView Demo\u003c/a\u003e\n    ·\n    \u003ca href=\"https://github.com/fkemser/SCwrapper/issues\"\u003eReport Bug\u003c/a\u003e\n    ·\n    \u003ca href=\"https://github.com/fkemser/SCwrapper/issues\"\u003eRequest Feature\u003c/a\u003e\n  \u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"res/screenshot2.png\" alt=\"screenshot2\" width=\"49%\"/\u003e \u003cimg src=\"res/screenshot3.png\" alt=\"screenshot3\" width=\"49%\"/\u003e  \n  \u003cimg src=\"res/screenshot4.png\" alt=\"screenshot4\" width=\"49%\"/\u003e \u003cimg src=\"res/screenshot5.png\" alt=\"screenshot5\" width=\"49%\"/\u003e\n\u003c/p\u003e\n\n\u003c!-- TABLE OF CONTENTS --\u003e\n\u003cdetails open\u003e\n  \u003csummary\u003eTable of Contents\u003c/summary\u003e\n  \u003col\u003e\n    \u003cli\u003e\u003ca href=\"#tldr\"\u003eTL;DR\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\n      \u003ca href=\"#about-the-project\"\u003eAbout The Project\u003c/a\u003e\n      \u003cul\u003e\n        \u003cli\u003e\u003ca href=\"#built-with\"\u003eBuilt With\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#related-projects\"\u003eRelated Projects\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#testing-environment\"\u003eTesting Environment\u003c/a\u003e\u003c/li\u003e\n      \u003c/ul\u003e\n    \u003c/li\u003e\n    \u003cli\u003e\n      \u003ca href=\"#getting-started\"\u003eGetting Started\u003c/a\u003e\n      \u003cul\u003e\n        \u003cli\u003e\u003ca href=\"#prerequisites\"\u003ePrerequisites\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#mandatory\"\u003eMandatory\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#interactive-mode-optional\"\u003eInteractive Mode (optional)\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#opensc-pkcs11-and-smartcard-hsm--nitrokey-hsm-2\"\u003eOpenSC PKCS#11 and SmartCard-HSM / Nitrokey HSM 2\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#opensc-pkcs15\"\u003eOpenSC PKCS#15\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#yubico-yubikey-piv\"\u003eYubico YubiKey PIV\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#pinpuk-letter-optional\"\u003ePIN/PUK Letter (optional)\u003c/a\u003e\u003c/li\u003e\n        \u003cli\u003e\u003ca href=\"#installation\"\u003eInstallation\u003c/a\u003e\u003c/li\u003e\n      \u003c/ul\u003e\n    \u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#usage\"\u003eUsage\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#examples-script-mode\"\u003eExamples (Script Mode)\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#help-script-mode\"\u003eHelp (Script Mode)\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#roadmap\"\u003eRoadmap\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#contributing\"\u003eContributing\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#license\"\u003eLicense\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#contact\"\u003eContact\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#acknowledgments\"\u003eAcknowledgments\u003c/a\u003e\u003c/li\u003e\n  \u003c/ol\u003e\n\u003c/details\u003e\n\n\n\n\u003c!-- TL;DR --\u003e\n## TL;DR\n\n### 1. Install dependencies\nTo install all (necessary and optional) packages on your system, simply run:\n\n#### Debian\n```sh\nsudo apt install dialog gnutls-bin opensc opensc-pkcs11 openssl \\\n                 pcscd libccid ykcs11 yubikey-manager\n```\n\nDepending on your token type not all packages may be needed. For more information please have a look at the [prerequisites](#prerequisites) section below.\n\nThis project provides a [customizable LaTeX letter template](#pinpuk-letter-optional) that can be used to print token-related secrets like PIN, PUK, etc.\n\n### 2. Clone the repo and run the script\n```sh\ngit clone --recurse-submodules https://github.com/fkemser/SCwrapper.git \u0026\u0026 \\\nchmod +x ./SCwrapper/src/sc.sh \u0026\u0026 \\\n./SCwrapper/src/sc.sh\n```\n\nFor more information please have a look at the [usage](#usage) and [examples](#examples-script-mode) section below.\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- ABOUT THE PROJECT --\u003e\n## About The Project\n\nThis project provides a shell script to\n\n- initialize a security token including setting secrets (PIN, PUK, etc.),\n- print initial secrets by using a customizable letter template,\n- import/export/delete certificates, keys, data objects from/to the token,\n- generate public-private key pairs,\n- change/reset/unblock PIN,\n- and much more.\n\nThe script can be controlled either via command-line switches or via an interactive, `dialog`-based interface.\n\nSo far, this project supports the following security token:\n\n- Smartcards and token that that are supported by [OpenSC (PKCS#11/PKCS#15)](https://github.com/OpenSC/OpenSC/wiki/Supported-hardware-%28smart-cards-and-USB-tokens%29)\n- [SmartCard-HSM / Nitrokey HSM 2](https://github.com/OpenSC/OpenSC/wiki/SmartCardHSM)\n- [Yubico YubiKey PIV](https://developers.yubico.com/PIV/Introduction/)\n\n\u003e :information_source: Please note that this project cannot cover all token-specific actions and options. For very specific use cases you should use the tools provided by your token manufacturer.\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n### Built With\n\n[![Shell Script][Shell Script-shield]][Shell Script-url]\n[![LaTeX][LaTeX-shield]][LaTeX-url]\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n### Related Projects\n\nThis work includes or is based on other projects:\n\n* [SHtemplate](https://github.com/fkemser/SHtemplate), a template for POSIX-/Bourne-Shell(sh) projects.\n* [CUPSwrapper](https://github.com/fkemser/CUPSwrapper), a collection of shell scripts to interactively print and manage printers for local usage.\n* [GerLaTeXLetter](https://github.com/fkemser/GerLaTeXLetter), a LaTeX template for business letters (mostly) following German DIN 5008 standard, based on KOMA-Script class `scrlttr2`.\n* [TeXLetterCreator](https://github.com/fkemser/TeXLetterCreator), a collection of shell scripts to interactively create and print TeX-based form letters.\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n### Testing Environment\n\nThe project has been developed and tested on the following system:\n\n| Info | Description\n---: | ---\nOS | Debian GNU/Linux 12 (bookworm)\nKernel | 5.15.133.1-microsoft-standard-WSL2\nPackages | [coreutils (9.1-1)](https://packages.debian.org/bookworm/coreutils)\n|| [dash (0.5.12-2)](https://packages.debian.org/bookworm/dash)\n|| [dialog (1.3-20230209-1)](https://packages.debian.org/bookworm/dialog)\n|| [libc-bin (2.36-9+deb12u3)](https://packages.debian.org/bookworm/libc-bin)\n|| [gnutls-bin (3.7.9-2+deb12u2)](https://packages.debian.org/bookworm/gnutls-bin)\n|| [libccid (1.5.2-1)](https://packages.debian.org/bookworm/libccid)\n|| [opensc (0.23.0-0.3+deb12u1)](https://packages.debian.org/bookworm/opensc)\n|| [opensc-pkcs11 (0.23.0-0.3+deb12u1)](https://packages.debian.org/bookworm/opensc-pkcs11)\n|| [openssl (3.0.11-1~deb12u2)](https://packages.debian.org/bookworm/openssl)\n|| [pcscd (1.9.9-2)](https://packages.debian.org/bookworm/pcscd)\n|| [ykcs11 (2.2.0-1.1)](https://packages.debian.org/bookworm/ykcs11)\n|| [yubikey-manager (4.0.9-1)](https://packages.debian.org/bookworm/yubikey-manager)\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- GETTING STARTED --\u003e\n## Getting Started\n### Prerequisites\nPlease make sure that the following dependencies are installed:\n\n* [PCSClite](https://pcsclite.apdu.fr/)\n* [USB PC/SC CCID driver](https://ccid.apdu.fr/)\n\nAdditionally, there are some use-case specific dependencies (see sections below):\n\n* [Dialog](https://invisible-island.net/dialog/dialog.html)\n* [GnuTLS](https://www.gnutls.org/)\n* [OpenSC](https://github.com/OpenSC/OpenSC)\n* [OpenSC (PKCS#11 module)](https://github.com/OpenSC/libp11)\n* [OpenSSL](https://www.openssl.org/)\n* [Yubico PIV tool (PKCS#11 module)](https://developers.yubico.com/yubico-piv-tool/)\n* [YubiKey Manager](https://developers.yubico.com/yubikey-manager/)\n\n### Mandatory\n```\n  Packages: PCSClite, USB PC/SC CCID driver\n    Debian: \u003e sudo apt install pcscd libccid\n```\n\n### Interactive Mode (optional)\nIn case you run this script interactively your terminal window must have a size of \u003c100x30\u003e or bigger.\n\n````\n  Packages: Dialog\n    Debian: \u003e sudo apt install dialog\n````\n\n### OpenSC PKCS#11 and SmartCard-HSM / Nitrokey HSM 2\n````\n  Packages: GnuTLS, OpenSC, OpenSC (PKCS#11 module)\n    Debian: \u003e sudo apt install gnutls-bin opensc opensc-pkcs11\n````\n\n### OpenSC PKCS#15\n````\n  Packages: OpenSC\n    Debian: \u003e sudo apt install opensc\n````\n\n### SmartCard-HSM / Nitrokey HSM 2\n````\n  Packages: OpenSSL\n    Debian: \u003e sudo apt install openssl\n````\n\n### Yubico YubiKey PIV\n[PIV PIN-only mode](https://docs.yubico.com/yesdk/users-manual/application-piv/pin-only.html) is currently not supported.\n\n````\n  Packages: GnuTLS, Yubico PIV tool (PKCS#11 module), YubiKey Manager\n    Debian: \u003e sudo apt install gnutls-bin ykcs11 yubikey-manager\n````\n\n### PIN/PUK Letter (optional)\n\n\u003ca href=\"res/letter.en.pdf\"\u003e\u003cimg src=\"res/letter.en.png\" alt=\"letter.en\" width=\"49%\"/\u003e\u003c/a\u003e \u003ca href=\"res/letter.de.pdf\"\u003e\u003cimg src=\"res/letter.de.png\" alt=\"letter.de\" width=\"49%\"/\u003e\u003c/a\u003e\n\nThis project provides a **LaTeX letter template** (`/tex/sc.tex`), a modified version of [GerLaTeXLetter](https://github.com/fkemser/GerLaTeXLetter).\nYou can use this template for **priting token-related secrets like PIN, PUK, etc.**.\n\n:warning: To use this feature **please follow all of the following setup instructions before continuing** :warning:\n  * [CUPSwrapper](https://github.com/fkemser/CUPSwrapper#prerequisites)\n  * [GerLaTeXLetter](https://github.com/fkemser/GerLaTeXLetter#prerequisites)\n  * [TeXLetterCreator](https://github.com/fkemser/TeXLetterCreator#prerequisites)\n\nAfterwards, please install some **additional but required CTAN packages**\n\n```sh\ntlmgr install environ microtype pgf tcolorbox tikzfill trimspaces\n```\n\n**To customize the template** please edit the files within the `/tex` folder. For more information please have a look at [GerLaTeXLetter](https://github.com/fkemser/GerLaTeXLetter#customization). The instructions for `letter.tex` also apply to `sc.tex`.\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n### Installation\n1. Make sure that your environment meets the [requirements](#prerequisites).\n\n2. Clone the repo\n\t```sh\n   git clone --recurse-submodules https://github.com/fkemser/SCwrapper.git\n   ```\n\n2. Edit the repository configuration file. In case it is empty just keep it as it is, **do not delete it**.\n\t```sh\n   nano ./SCwrapper/etc/sc.cfg.sh\n   ```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- USAGE --\u003e\n## Usage\n\n\u003cimg src=\"res/usage.gif\" alt=\"usage\" width=\"100%\"/\u003e\n\nTo call the script **interactively**, run `/src/sc.sh` (without further arguments) from your terminal.\n\nFor **script mode** run `/src/sc.sh` followed by a list of arguments `--arg1 [\u003cval1\u003e] --arg2 [\u003cval2\u003e] ...`, see also [help](#help-script-mode) section below.\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- EXAMPLES (SCRIPT MODE) --\u003e\n## Examples (Script Mode)\n\n[1. Initialize token](#1-initialize-token)  \n[2. Generate public-private key pair](#2-generate-public-private-key-pair)  \n[3. Import certificate / key / data object](#3-import-certificate--key--data-object)  \n[4. Export certificate / data object](#4-export-certificate--data-object)  \n[5. Delete certificate / key / data object](#5-delete-certificate--key--data-object)  \n[6. PIN Management (Change/Reset/Unblock)](#6-pin-management-changeresetunblock)  \n[7. Backup and restore private key (SmartCard-HSM / Nitrokey HSM 2 only)](#7-backup-and-restore-private-key-smartcard-hsm--nitrokey-hsm-2-only)\n\n### 1. Initialize token\n```sh\nexport pin=\"1111\"\nexport puk=\"123456\"\nexport sopin=\"123456\"\nexport sopuk=\"123456\"\nexport password=\"secret\"\nexport mgmtkey=\"010203040506070801020304050607080102030405060708\"\n```\n\n#### OpenSC PKCS#11 ('-T opensc-p11')\n```sh\n./sc.sh -T opensc-p11 --initialize --label mytoken --pin env:pin --so-pin env:sopin\n```\n\n#### OpenSC PKCS#15 ('-T opensc-p15')\n```sh\n# Step 1 - Erase PKCS#15 structure (certain models only)\n  ./sc.sh -T opensc-p15 --erase-card\n\n# Step 2 - Initialize token (all models)\n# Token supports a separate SO-PIN/SO-PUK pair\n  ./sc.sh -T opensc-p15 --initialize --pin env:pin --puk env:puk --so-pin env:sopin --so-puk env:sopuk\n# Token only supports one PIN/PUK pair\n  ./sc.sh -T opensc-p15 --initialize --opensc-p15-profile pkcs15+onepin --pin env:pin --puk env:puk\n\n# Step 3 - Finish initialization (certain models only)\n  ./sc.sh -T opensc-p15 --finalize\n```\n\n#### SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')\n```sh\n# Initialize without any DKEK (= key backup/restore disabled)\n./sc.sh -T schsm --initialize --pin env:pin --so-pin env:sopin\n\n# Initialize with 1 DKEK share, with a single password (no threshold scheme)\n./sc.sh -T schsm --initialize --pin env:pin --so-pin env:sopin --schsm-dkek-shares 1\n./sc.sh -T schsm --schsm-dkek-share-create dkek-share-1.pbe --password env:password\n./sc.sh -T schsm --schsm-dkek-share-import dkek-share-1.pbe\n\n# Initialize with 1 DKEK share and a 2-of-4 threshold scheme\n./sc.sh -T schsm --initialize --pin env:pin --so-pin env:sopin --schsm-dkek-shares 1\n./sc.sh -T schsm --schsm-dkek-share-create dkek-share-1.pbe --schsm-pwd-shares-threshold 2 --schsm-pwd-shares-total 4\n./sc.sh -T schsm --schsm-dkek-share-import dkek-share-1.pbe --schsm-pwd-shares-total 2\n```\n\n#### Yubico YubiKey PIV ('-T yubico')\n```sh\n./sc.sh -T yubico --initialize --pin env:pin --puk env:puk --yubico-management-key env:mgmtkey\n```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#examples-script-mode\"\u003eback to overview\u003c/a\u003e)\u003c/p\u003e\n\n### 2. Generate public-private key pair\n#### OpenSC PKCS#11 ('-T opensc-p11') and SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')\n```sh\n./sc.sh -T \u003c...\u003e --keypairgen --id 10 --key-type rsa:2048\n./sc.sh -T \u003c...\u003e --keypairgen --label mykey --key-type rsa:2048\n```\n\n#### OpenSC PKCS#15 ('-T opensc-p15')\n```sh\n./sc.sh -T opensc-p15 --keypairgen --id 10 --key-type rsa/2048\n./sc.sh -T opensc-p15 --keypairgen --label mykey --key-type rsa/2048\n```\n\n#### Yubico YubiKey PIV ('-T yubico')\n```sh\n./sc.sh -T yubico --keypairgen \"pubkey.pem\" --format pem --piv-slot 9A --key-type RSA2048\n```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#examples-script-mode\"\u003eback to overview\u003c/a\u003e)\u003c/p\u003e\n\n### 3. Import certificate / key / data object\n#### OpenSC PKCS#11 ('-T opensc-p11') and SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')\n```sh\n./sc.sh -T \u003c...\u003e  --import cert.der   --type cert     --id 10   --label mycert\n./sc.sh -T \u003c...\u003e  --import key.der    --type privkey  --id 20   --label mykey\n./sc.sh -T \u003c...\u003e  --import data.file  --type data     --id 30   --label mydata\n```\n\n#### OpenSC PKCS#15 ('-T opensc-p15')\n```sh\n./sc.sh -T opensc-p15   --import cert.pem   --type cert     --id 10   --label mycert\n./sc.sh -T opensc-p15   --import cert.der   --type cert     --id 10   --label mycert  --format der\n./sc.sh -T opensc-p15   --import key.pem    --type privkey  --id 20   --label mykey\n./sc.sh -T opensc-p15   --import key.p12    --type privkey  --id 20   --label mykey   --format pkcs12\n./sc.sh -T opensc-p15   --import data.file  --type data               --label mydata\n```\n\n#### Yubico YubiKey PIV ('-T yubico')\n```sh\n./sc.sh -T yubico   --import cert.pem   --type cert     --piv-slot 9A   --format pem\n./sc.sh -T yubico   --import key.der    --type privkey  --piv-slot 9A   --format der\n./sc.sh -T yubico   --import data.file  --type data     --piv-id 5FC108\n```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#examples-script-mode\"\u003eback to overview\u003c/a\u003e)\u003c/p\u003e\n\n### 4. Export certificate / data object\n#### OpenSC PKCS#11 ('-T opensc-p11') and SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')\n```sh\n./sc.sh -T \u003c...\u003e    --export cert.der   --type cert   ( --id 10 | --label mycert )\n./sc.sh -T \u003c...\u003e    --export data.file  --type data   --label mydata\n```\n\n#### OpenSC PKCS#15 ('-T opensc-p15')\n```sh\n./sc.sh -T opensc-p15   --export cert.der   --type cert   --id 10\n./sc.sh -T opensc-p15   --export data.file  --type data   --label mydata\n```\n\n#### Yubico YubiKey PIV ('-T yubico')\n```sh\n./sc.sh -T yubico   --export cert.der   --type cert   --piv-slot 9A   --format der\n./sc.sh -T yubico   --export cert.pem   --type cert   --piv-slot 9A   --format pem\n./sc.sh -T yubico   --export data.file  --type data   --piv-id 5FC108\n```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#examples-script-mode\"\u003eback to overview\u003c/a\u003e)\u003c/p\u003e\n\n### 5. Delete certificate / key / data object\n#### OpenSC PKCS#11 ('-T opensc-p11') and SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')\n```sh\n./sc.sh -T \u003c...\u003e  --delete  --type cert     ( --id 10 | --label mycert )\n./sc.sh -T \u003c...\u003e  --delete  --type privkey  ( --id 20 | --label mykey )\n./sc.sh -T \u003c...\u003e  --delete  --type data     --label mydata  --data-application-name \u003cname\u003e\n./sc.sh -T \u003c...\u003e  --delete  --type data     --data-oid \u003coid\u003e\n```\n\n#### OpenSC PKCS#15 ('-T opensc-p15')\n```sh\n./sc.sh -T opensc-p15   --delete  --type cert     --id 10\n./sc.sh -T opensc-p15   --delete  --type privkey  --id 20\n./sc.sh -T opensc-p15   --delete  --type data     --label mydata  --data-application-name \u003cname\u003e\n./sc.sh -T opensc-p15   --delete  --type data     --data-oid \u003coid\u003e\n```\n\n#### Yubico YubiKey PIV ('-T yubico')\n```sh\n./sc.sh -T yubico --delete --type cert --piv-slot 9A\n```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#examples-script-mode\"\u003eback to overview\u003c/a\u003e)\u003c/p\u003e\n\n### 6. PIN Management (Change/Reset/Unblock)\n```sh\nexport oldpin=\"1111\"\nexport newpin=\"2222\"\nexport puk=\"123456\"\nexport sopin=\"123456\"\n\n./sc.sh -T \u003c...\u003e --change-pin  --pin env:oldpin    --new-pin env:newpin\n./sc.sh -T \u003c...\u003e --reset-pin   --so-pin env:sopin  --new-pin env:newpin\n./sc.sh -T \u003c...\u003e --unblock-pin --puk env:puk       --new-pin env:newpin\n```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#examples-script-mode\"\u003eback to overview\u003c/a\u003e)\u003c/p\u003e\n\n### 7. Backup and restore private key (SmartCard-HSM / Nitrokey HSM 2 only)\n```sh\n./sc.sh -T schsm  --schsm-backup  wrap-key.bin  --schsm-key-reference 1\n./sc.sh -T schsm  --schsm-restore wrap-key.bin  --schsm-key-reference 10\n```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- HELP (SCRIPT MODE) --\u003e\n## Help (Script Mode)\nTo get help, run `./SCwrapper/src/sc.sh -h`.  \n\n```sh\n================================================================================\n===============================     SYNOPSIS     ===============================\n================================================================================\n\nThere are multiple ways to run this script:\n\nInteractive mode (without any args):\n\u003e ./sc.sh\n\nClassic (script) mode:\n\u003e ./sc.sh [ OPTION ]... ACTION\n\nOpenSC PKCS#11         ./sc.sh [ -T opensc-p11 ] [ OPTION ]... ACTION           \n(default)                                                                       \n                                                                                \n                       ACTION := { -h|--help | --change-pin | --change-so-pin | \n                       --connect | --delete | --export \u003cfile\u003e | --get \u003ctype\u003e |  \n                       --import \u003cfile\u003e | --initialize | --keypairgen [\u003cfile\u003e] | \n                       --list \u003ctype\u003e | --p11-get-uri \u003ctype\u003e | --reset-pin }     \n                                                                                \n                       OPTION := { [--data-application-name \u003cname\u003e] |           \n                       [--data-oid \u003coid\u003e] | [-f|--format \u003cformat\u003e] | [-i|--id   \n                       \u003cid\u003e] | [--key-type \u003ctype\u003e] | [-l|--label \u003clabel\u003e] |     \n                       [-n|--new-pin|--new-puk| --new-so-pin \u003cval\u003e] |           \n                       [--password \u003cpwd\u003e] | [-p|--pin \u003cpin\u003e] | [-P|--puk \u003cpuk\u003e] \n                       | [-r|--reader \u003cid\u003e] | [-s|--so-pin \u003cso pin\u003e] |          \n                       [-S|--so-puk \u003cso puk\u003e] | [-t|--type \u003ctype\u003e] }            \n\nOpenSC PKCS#15         ./sc.sh -T opensc-p15 [ OPTION ]... ACTION               \n                                                                                \n                       ACTION := { -h|--help | --change-pin | --change-puk |    \n                       --change-so-pin | --connect | --delete |                 \n                       --erase-application \u003caid\u003e | --erase-card | --export      \n                       \u003cfile\u003e | --finalize | --get \u003ctype\u003e | --import \u003cfile\u003e |   \n                       --initialize | --keypairgen [\u003cfile\u003e] | --list \u003ctype\u003e |   \n                       --store-pin | --unblock-pin }                            \n                                                                                \n                       OPTION := { [--data-application-name \u003cname\u003e] |           \n                       [--data-oid \u003coid\u003e] | [-f|--format \u003cformat\u003e] | [-i|--id   \n                       \u003cid\u003e] | [--key-type \u003ctype\u003e] | [-l|--label \u003clabel\u003e] |     \n                       [-n|--new-pin|--new-puk| --new-so-pin \u003cval\u003e] |           \n                       [--opensc-p15-profile \u003cprofile\u003e] | [--p15-aid \u003cid\u003e] |    \n                       [--p15-auth-id \u003cid\u003e] | [--password \u003cpwd\u003e] | [-p|--pin    \n                       \u003cpin\u003e] | [-P|--puk \u003cpuk\u003e] | [-r|--reader \u003cid\u003e] |         \n                       [-s|--so-pin \u003cso pin\u003e] | [-S|--so-puk \u003cso puk\u003e] |        \n                       [-t|--type \u003ctype\u003e] }                                     \n\nSmartCard-HSM /        ./sc.sh -T schsm [ OPTION ]... ACTION                    \nNitrokey HSM 2                                                                  \n                                                                                \n                       ACTION := { -h|--help | --change-pin | --change-so-pin | \n                       --connect | --delete | --export \u003cfile\u003e | --get \u003ctype\u003e |  \n                       --import \u003cfile\u003e | --initialize | --keypairgen [\u003cfile\u003e] | \n                       --list \u003ctype\u003e | --p11-get-uri \u003ctype\u003e | --reset-pin |     \n                       --schsm-backup \u003cfile\u003e | --schsm-dkek-share-create \u003cfile\u003e \n                       | --schsm-dkek-share-import \u003cfile\u003e | --schsm-restore     \n                       \u003cfile\u003e }                                                 \n                                                                                \n                       OPTION := { [-F|--force] | [-f|--format \u003cformat\u003e] |      \n                       [-i|--id \u003cid\u003e] | [--key-type \u003ctype\u003e] | [-l|--label       \n                       \u003clabel\u003e] | [-n|--new-pin|--new-puk| --new-so-pin \u003cval\u003e]  \n                       | [--password \u003cpwd\u003e] | [-p|--pin \u003cpin\u003e] | [-P|--puk      \n                       \u003cpuk\u003e] | [-r|--reader \u003cid\u003e] | [--schsm-dkek-shares       \n                       \u003cint\u003e] | [--schsm-key-reference \u003cid\u003e] |                  \n                       [--schsm-pwd-shares-threshold \u003cint\u003e] |                   \n                       [--schsm-pwd-shares-total \u003cint\u003e] | [-s|--so-pin \u003cso      \n                       pin\u003e] | [-S|--so-puk \u003cso puk\u003e] | [-t|--type \u003ctype\u003e] }    \n\nYubico YubiKey PIV     ./sc.sh -T yubico [ OPTION ]... ACTION                   \n                                                                                \n                       ACTION := { -h|--help | --change-management-key |        \n                       --change-pin | --change-puk | --connect | --delete |     \n                       --export \u003cfile\u003e | --get \u003ctype\u003e | --import \u003cfile\u003e |       \n                       --initialize | --keypairgen [\u003cfile\u003e] | --list \u003ctype\u003e |   \n                       --p11-get-uri \u003ctype\u003e | --unblock-pin }                   \n                                                                                \n                       OPTION := { [-F|--force] | [-f|--format \u003cformat\u003e] |      \n                       [--key-type \u003ctype\u003e] | [-n|--new-pin|--new-puk|           \n                       --new-so-pin \u003cval\u003e] | [--password \u003cpwd\u003e] | [-p|--pin     \n                       \u003cpin\u003e] | [--piv-id \u003cid\u003e] | [--piv-slot \u003cid\u003e] | [-P|--puk \n                       \u003cpuk\u003e] | [--serial \u003cserial no\u003e] | [-s|--so-pin \u003cso pin\u003e] \n                       | [-S|--so-puk \u003cso puk\u003e] | [-t|--type \u003ctype\u003e] |          \n                       [--yubico-management-key \u003ckey\u003e] |                        \n                       [--yubico-new-management-key \u003ckey\u003e] |                    \n                       [--yubico-pin-policy \u003cpol\u003e] | [--yubico-touch-policy     \n                       \u003cpol\u003e] }                                                 \n\n--------------------------------------------------------------------------------\n--------------------------------     ACTION     --------------------------------\n--------------------------------------------------------------------------------\n\n__________________________ Miscellaneous Token Types ___________________________\n\nSome actions are only allowed with certain token types, see type-specific action lists above.\n\n--change-pin              Change user PIN (requires user PIN). See also         \n                          '-p|--pin \u003cpin\u003e' and '-n|--new-pin|--new-puk|         \n                          --new-so-pin \u003cval\u003e'.                                  \n\n--change-puk              Change user PUK. Only with '-T opensc-p15' or '-T     \n                          yubico'. See also '-P|--puk \u003cpuk\u003e' and                \n                          '-n|--new-pin|--new-puk|                              \n                          --new-so-pin \u003cval\u003e'.                                  \n\n--change-so-pin           Change security officer PIN (SO-PIN). Only with '-T   \n                          opensc-p11', '-T opensc-p15', or '-T schsm'. See also \n                          '-s|--so-pin \u003cso pin\u003e' and '-n|--new-pin|--new-puk|   \n                          --new-so-pin \u003cval\u003e'.                                  \n\n--connect                 Prompt the user interactively to connect a token.     \n                          Returns '0' (token connected) or '1' (no token found).\n\n--delete                  Delete a certificate, key, or data object on the      \n                          token. Object type must be specified using '-t|--type \n                          \u003ctype\u003e'.                                              \n                                                                                \n                          ***** OpenSC PKCS#11 ('-T opensc-p11') *****          \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                          ***** SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')     \n                          *****                                                 \n                          Use '-p|--pin \u003cpin\u003e' or '-s|--so-pin \u003cso pin\u003e' to     \n                          specify the PIN or SO-PIN to use.                     \n                                                                                \n                            \u003ctype\u003e = data                                       \n                          Use '--data-oid \u003coid\u003e' or '--data-application-name    \n                          \u003cname\u003e' and '-l|--label \u003clabel\u003e' to specify the data  \n                          object to delete.                                     \n                                                                                \n                            \u003ctype\u003e != data                                      \n                          Use '-i|--id \u003cid\u003e' and/or '-l|--label \u003clabel\u003e' (not   \n                          with '-T opensc-p15') to specify the object to delete.\n                                                                                \n                          \u003ctype\u003e = { cert | data | privkey | pubkey | secrkey } \n                                                                                \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                          Use '--p15-aid \u003cid\u003e' to specify the target            \n                          application when using multi-application cards.       \n                                                                                \n                          \u003ctype\u003e = { cert | chain | data | privkey | pubkey |   \n                          secrkey }                                             \n                                                                                \n                          ***** Yubico YubiKey PIV ('-T yubico') *****          \n                          Use '--piv-slot \u003cid\u003e' to specify the PIV slot to      \n                          operate on. Use '--yubico-management-key \u003ckey\u003e' to    \n                          specify the current management key.                   \n                                                                                \n                          \u003ctype\u003e = { cert }                                     \n\n--export \u003cfile\u003e           Export a certificate, public key, or data object from \n                          the token to a \u003cfile\u003e. Object type must be specified  \n                          using '-t|--type \u003ctype\u003e'.                             \n                                                                                \n                          ***** OpenSC PKCS#11 ('-T opensc-p11') *****          \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                          ***** SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')     \n                          *****                                                 \n                                                                                \n                            \u003ctype\u003e = data                                       \n                          Use '-l|--label \u003clabel\u003e', '--data-oid \u003coid\u003e' or       \n                          '--data-application-name \u003cname\u003e' to specify the data  \n                          object to export.                                     \n                                                                                \n                            \u003ctype\u003e != data                                      \n                          Use '-i|--id \u003cid\u003e' and/or '-l|--label \u003clabel\u003e' (not   \n                          with '-T opensc-p15') to specify the object to export.\n                                                                                \n                          \u003ctype\u003e = { cert | data | pubkey }                     \n                                                                                \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                          Use '-p|--pin \u003cpin\u003e' or '-s|--so-pin \u003cso pin\u003e' to     \n                          specify the PIN or SO-PIN to use (only if \u003ctype\u003e =    \n                          data). Use '--p15-aid \u003cid\u003e' to specify the target     \n                          application when using multi-application cards.       \n                                                                                \n                          \u003ctype\u003e = { cert | data | pubkey | sshkey |            \n                          sshkey-rfc4716 }                                      \n                                                                                \n                          ***** Yubico YubiKey PIV ('-T yubico') *****          \n                          Use '-f|--format \u003cformat\u003e' to specify the             \n                          certificate/key format. Use '--piv-slot \u003cid\u003e' to      \n                          specify the PIV slot to operate on (only if \u003ctype\u003e =  \n                          { cert | pubkey }). Use '--piv-id \u003cid\u003e' to specify    \n                          the PIV object id (BER-TLV tag) to use (only if       \n                          \u003ctype\u003e = data). Use '-p|--pin \u003cpin\u003e' to specify the   \n                          PIN to use (only if \u003ctype\u003e = { data | pubkey }).      \n                                                                                \n                          \u003ctype\u003e = { cert | data | pubkey }                     \n\n--get \u003ctype\u003e              Get information about the smartcard or its reader.    \n                          Exactly one (1) token must be connected at that time. \n                                                                                \n                          ***** OpenSC PKCS#11 ('-T opensc-p11') *****          \n                          ***** SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')     \n                          *****                                                 \n                          ***** Yubico YubiKey PIV ('-T yubico') *****          \n                                                                                \n                          \u003ctype\u003e = { reader | smartcard |                       \n                          smartcard-manufacturer | smartcard-model |            \n                          smartcard-serial }                                    \n                                                                                \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                                                                                \n                          \u003ctype\u003e = { reader | smartcard | smartcard-model |     \n                          smartcard-serial }                                    \n\n--import \u003cfile\u003e           Import a certificate, key, or data object from a      \n                          \u003cfile\u003e to the token. Object type must be specified    \n                          using '-t|--type \u003ctype\u003e'. For password-protected      \n                          files use '--password \u003cpwd\u003e' to specify/set the       \n                          password.                                             \n                                                                                \n                          ***** OpenSC PKCS#11 ('-T opensc-p11') *****          \n                          ***** SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')     \n                          *****                                                 \n                          Object must be specified via '-i|--id \u003cid\u003e' and/or    \n                          '-l|--label \u003clabel\u003e'. \u003cfile\u003e must be DER-encoded. To  \n                          convert from PEM to DER format, just run 'openssl     \n                          x509 -in \u003cfile_in\u003e.pem -out \u003cfile_out\u003e.der -outform   \n                          der'. Use '-p|--pin \u003cpin\u003e' to specify the PIN to use. \n                                                                                \n                            \u003ctype\u003e = data                                       \n                          Optionally use '--data-oid \u003coid\u003e' to specify the data \n                          object's identifier (OID). Optionally use             \n                          '--data-application-name \u003cname\u003e' to specify the data  \n                          object's application name.                            \n                                                                                \n                          \u003ctype\u003e = { cert | data | privkey | pubkey | secrkey } \n                                                                                \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                          Use '-p|--pin \u003cpin\u003e' or '-s|--so-pin \u003cso pin\u003e' to     \n                          specify the PIN or SO-PIN to use. Use '--p15-aid      \n                          \u003cid\u003e' to specify the target application when using    \n                          multi-application cards.                              \n                                                                                \n                            \u003ctype\u003e = data                                       \n                          Optionally use '-l|--label \u003clabel\u003e' to specify object \n                          label (name). Optionally use '--data-oid \u003coid\u003e' to    \n                          specify the data object's identifier (OID).           \n                          Optionally use '--data-application-name \u003cname\u003e' to    \n                          specify the data object's application name.           \n                                                                                \n                            \u003ctype\u003e != data                                      \n                          Optionally use '-i|--id \u003cid\u003e' and/or '-l|--label      \n                          \u003clabel\u003e' to specify an object. Use '-f|--format       \n                          \u003cformat\u003e' to specify the certificate/key format.      \n                                                                                \n                          \u003ctype\u003e = { cert | data | privkey | pubkey | secrkey } \n                                                                                \n                          ***** Yubico YubiKey PIV ('-T yubico') *****          \n                          Use '-f|--format \u003cformat\u003e' to specify the             \n                          certificate/key format. Use '--piv-slot \u003cid\u003e' to      \n                          specify the PIV slot to operate on (only if \u003ctype\u003e =  \n                          { cert | privkey }). Use '--piv-id \u003cid\u003e' to specify   \n                          the PIV object id (BER-TLV tag) to use (only if       \n                          \u003ctype\u003e = data). Use '--yubico-management-key \u003ckey\u003e'   \n                          to specify the current management key.                \n                                                                                \n                          \u003ctype\u003e = { cert | data | privkey }                    \n\n--initialize              Initialize token                                      \n                                                                                \n                          ***** OpenSC PKCS#11 ('-T opensc-p11') *****          \n                          Set token label, SO-PIN, and PIN. Object to create or \n                          operate on must be specified via '-l|--label \u003clabel\u003e'.\n                                                                                \n                          Use '-p|--pin \u003cpin\u003e' and '-s|--so-pin \u003cso pin\u003e' to    \n                          set PIN and SO-PIN.                                   \n                                                                                \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                          Create initial PKCS#15 data structure. Optionally use \n                          '-l|--label \u003clabel\u003e' to specify object label (name).  \n                                                                                \n                          Use '-p|--pin \u003cpin\u003e', '-P|--puk \u003cpuk\u003e', '-s|--so-pin  \n                          \u003cso pin\u003e', and '-S|--so-puk \u003cso puk\u003e' to set PIN,     \n                          PUK, SO-PIN, and SO-PUK. Please note that certain     \n                          models only support one PIN/PUK pair but no           \n                          additional SO-PIN/SO-PUK.                             \n                                                                                \n                          Use '--opensc-p15-profile \u003cprofile\u003e' to specify the   \n                          OpenSC PKCS#15 profile to load during initialization, \n                          e.g. 'pkcs15+onepin' in case your token only supports \n                          one user PIN/PUK pair but no additional SO-PIN/SO-PUK.\n                                                                                \n                          With certain models it is necessary to run './sc.sh   \n                          --erase-card' before and/or './sc.sh --finalize'      \n                          after initialization.                                 \n                                                                                \n                          ***** SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')     \n                          *****                                                 \n                          Remove all existing keys, certificates and files. Use \n                          it with '--schsm-dkek-shares \u003cint\u003e' to enable private \n                          key backup/restore, this can not(!) be done at a      \n                          later stage.                                          \n                                                                                \n                          Use '-p|--pin \u003cpin\u003e' and '-s|--so-pin \u003cso pin\u003e' to    \n                          set PIN and SO-PIN.                                   \n                                                                                \n                          ***** Yubico YubiKey PIV ('-T yubico') *****          \n                          Wipe all PIV-related data and restore PIV application \n                          to factory settings.                                  \n                                                                                \n                          Use '-p|--pin \u003cpin\u003e', '-P|--puk \u003cpuk\u003e', and           \n                          '--yubico-management-key \u003ckey\u003e' to set PIN, PUK, and  \n                          management key.                                       \n\n--keypairgen [\u003cfile\u003e]     Generate a public-private key pair. \u003cfile\u003e is only    \n                          possible (and mandatory) with '-T yubico'. Optionally \n                          use '--key-type \u003ctype\u003e' to specify key type/length.   \n                                                                                \n                          ***** OpenSC PKCS#11 ('-T opensc-p11') *****          \n                          ***** SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')     \n                          *****                                                 \n                          Object must be specified via '-i|--id \u003cid\u003e' and/or    \n                          '-l|--label \u003clabel\u003e'. Use '-p|--pin \u003cpin\u003e' to specify \n                          the PIN to use.                                       \n                                                                                \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                          Optionally use '-i|--id \u003cid\u003e' and/or '-l|--label      \n                          \u003clabel\u003e' to specify an object. Use '-p|--pin \u003cpin\u003e'   \n                          or '-s|--so-pin \u003cso pin\u003e' to specify the PIN or       \n                          SO-PIN to use. Use '--p15-aid \u003cid\u003e' to specify the    \n                          target application when using multi-application cards.\n                                                                                \n                          ***** Yubico YubiKey PIV ('-T yubico') *****          \n                          It is mandatory to set \u003cfile\u003e to specify where the    \n                          (generated) public key should be saved to. Use        \n                          '-f|--format \u003cformat\u003e' to specify the certificate/key \n                          format. Use '--piv-slot \u003cid\u003e' to specify the PIV slot \n                          to operate on. Use '--yubico-management-key \u003ckey\u003e' to \n                          specify the current management key.                   \n\n--list \u003ctype\u003e             List available objects, supported mechanisms, etc.    \n                                                                                \n                          ***** OpenSC PKCS#11 ('-T opensc-p11') *****          \n                          \u003ctype\u003e = { algorithm | object | reader }              \n                                                                                \n                          ***** OpenSC PKCS#15 ('-T opensc-p15') *****          \n                          Use '--p15-aid \u003cid\u003e' to specify the target            \n                          application when using multi-application cards.       \n                                                                                \n                          \u003ctype\u003e = { algorithm | cert | data | info | object |  \n                          privkey | pubkey | reader | secrkey | p15-application \n                          | p15-pin }                                           \n                                                                                \n                          \u003ctype\u003e = { data | privkey | secrkey }                 \n                          Use '-p|--pin \u003cpin\u003e' or '-s|--so-pin \u003cso pin\u003e' to     \n                          specify the PIN or SO-PIN to use (certain models      \n                          only).                                                \n                                                                                \n                          ***** SmartCard-HSM / Nitrokey HSM 2 ('-T schsm')     \n                          *****                                                 \n                          \u003ctype\u003e = { algorithm | object | reader }              \n                                                                                \n                          ***** Yubico YubiKey PIV ('-T yubico') *****          \n                          \u003ctype\u003e = { algorithm | data | info | reader }         \n\n--p11-get-uri \u003ctype\u003e      Interactively select a token object and get its       \n                          PKCS#11 URI. Only with '-T opensc-p11', '-T schsm',   \n                          or '-T yubico'. \u003ctype\u003e acts as an object filter,      \n                          possible values are:                                  \n                                                                                \n                                all  :  All available objects                   \n                          all-certs  :  All available certificates              \n                              certs  :  Only certificates that                  \n                                        have an associated                      \n                                        private key                             \n                           privkeys  :  All available private keys              \n                                                                                \n                          (default: 'all')                                      \n\n--reset-pin               Reset user PIN (requires SO-PIN). Only with '-T       \n                          opensc-p11' or '-T schsm'. See also                   \n                          '-n|--new-pin|--new-puk|                              \n                          --new-so-pin \u003cval\u003e' and '-s|--so-pin \u003cso pin\u003e'.       \n\n--unblock-pin             Reset user PIN (requires user PUK). Only with '-T     \n                          opensc-p11', '-T opensc-p15', or '-T yubico'. See     \n                          also '-n|--new-pin|--new-puk|                         \n                          --new-so-pin \u003cval\u003e' and '-P|--puk \u003cpuk\u003e'.             \n\n________________________________ OpenSC PKCS#15 ________________________________\n\n--erase-application \u003caid\u003e     Erase PKCS#15 application with the (hexadecimal)  \n                              application identifier \u003caid\u003e, see also '--p15-aid \n                              \u003cid\u003e'. Use '-p|--pin \u003cpin\u003e' or '-s|--so-pin \u003cso   \n                              pin\u003e' to specify the PIN or SO-PIN to use.        \n\n--erase-card                  Erase PKCS#15 structure (certain models only).    \n                              Use '-p|--pin \u003cpin\u003e' or '-s|--so-pin \u003cso pin\u003e' to \n                              specify the PIN or SO-PIN to use.                 \n\n--finalize                    Finish initialization (certain models only).      \n                              Depending on the model this may prevent you from  \n                              adding new private/secret keys and/or PIN/PUK     \n                              pairs. For further information please have a look \n                              at OpenSC's model-specific wiki pages:            \n                                https://github.com/OpenSC/OpenSC/wiki           \n\n--store-pin                   Add another user PIN/PUK pair. Use '-p|--pin      \n                              \u003cpin\u003e' and '-P|--puk \u003cpuk\u003e' to set PIN and PUK.   \n                              Use '--p15-auth-id \u003cid\u003e' to specify the           \n                              hexadecimal auth id of PIN/PUK pair to            \n                              use/create. Optionally use '-l|--label \u003clabel\u003e'   \n                              to specify object label (name).                   \n\n________________________ SmartCard-HSM / Nitrokey HSM 2 ________________________\n\n--schsm-backup \u003cfile\u003e                Export private key and store it in \u003cfile\u003e  \n                                     (DKEK-encrypted). Use it with              \n                                     '--schsm-key-reference \u003cid\u003e' to specify    \n                                     the key (identifier) to use. Use '-p|--pin \n                                     \u003cpin\u003e' to specify the PIN to use.          \n\n--schsm-dkek-share-create \u003cfile\u003e     Create an encrypted DKEK share and save it \n                                     into \u003cfile\u003e. Please print the file's       \n                                     content on paper in case the file gets     \n                                     corrupted. To get a printable version, run \n                                     'openssl base64 -in \u003cfile\u003e'.               \n                                                                                \n                                     Use '--password \u003cpwd\u003e' to specify an       \n                                     encryption password, otherwise you will be \n                                     prompted for one.                          \n                                                                                \n                                     Use '--schsm-pwd-shares-threshold \u003cint\u003e'   \n                                     and '--schsm-pwd-shares-total \u003cint\u003e' to    \n                                     establish an n-of-m threshold scheme. Do   \n                                     not(!) use '--password \u003cpwd\u003e' in this      \n                                     case, you will be prompted for the         \n                                     password shares. See also:                 \n                                     https://github.com/OpenSC/OpenSC/wiki/Smart\n                                     CardHSM#using-a-n-of-m-threshold-scheme    \n\n--schsm-dkek-share-import \u003cfile\u003e     Decrypt and write DKEK share from \u003cfile\u003e   \n                                     to the HSM.                                \n                                                                                \n                                     Use '--password \u003cpwd\u003e' to specify the      \n                                     decryption password, otherwise you will be \n                                     prompted for one.                          \n                                                                                \n                                     Use it with '--schsm-pwd-shares-total      \n                                     \u003cint\u003e' in case your DKEK share requires    \n                                     \u003cint\u003e password shares to restore it. Do    \n                                     not(!) use '--password \u003cpwd\u003e' in this      \n                                     case, you will be prompted for the         \n                                     password shares. See also:                 \n                                     https://github.com/OpenSC/OpenSC/wiki/Smart\n                                     CardHSM#using-a-n-of-m-threshold-scheme    \n\n--schsm-restore \u003cfile\u003e               Restore private key from \u003cfile\u003e            \n                                     (DKEK-encrypted). Use it with              \n                                     '--schsm-key-reference \u003cid\u003e' to specify    \n                                     the key reference to use. This mode        \n                                     requires running './sc.sh --initialize     \n                                     --schsm-dkek-shares \u003cint\u003e' and './sc.sh    \n                                     --schsm-dkek-share-import \u003cfile\u003e'          \n                                     beforehand. Use '-p|--pin \u003cpin\u003e' to        \n                                     specify the PIN to use.                    \n\n______________________________ Yubico YubiKey PIV ______________________________\n\n--change-management-key     Change management key. Use '--yubico-management-key \n                            \u003ckey\u003e' to specify the current management key. Use   \n                            '--yubico-new-management-key \u003ckey\u003e' to specify the  \n                            new management key.                                 \n\n--------------------------------------------------------------------------------\n--------------------------------     OPTION     --------------------------------\n--------------------------------------------------------------------------------\n\n__________________________ Miscellaneous Token Types ___________________________\n\nSome options are only allowed with certain token types, see type-specific option lists above.\n\n-T|--token-type \u003ctype\u003e             Select the token type to use                 \n                                                                                \n                                   \u003ctype\u003e = { opensc-p11 | opensc-p15 | schsm | \n                                   yubico }                                     \n                                                                                \n                                   (default: 'opensc-p11')                      \n\n--data-application-name \u003cname\u003e     Specify the application name of the data     \n                                   object to import. Only with '-T opensc-p11'  \n                                   or '-T opensc-p15'. Run './sc.sh --list      \n                                   data' to list all available data objects.    \n\n--data-oid \u003coid\u003e                   Specify the data object's identifier (OID).  \n                                   Run './sc.sh --list data' to list all        \n                                   available data objects.                      \n\n-F|--force                         Perform action without any further user      \n                                   interaction. Only with '-T schsm             \n                                   --schsm-restore \u003cfile\u003e' or '-T yubico        \n                                   (--initialize|--change-management-key)'.     \n\n-f|--format \u003cformat\u003e               Certificate or key format to use. 'pkcs12'   \n                                   is only possible with '-T opensc-p15         \n                                   --import \u003cfile\u003e --type privkey'.             \n                                                                                \n                                   \u003cformat\u003e = { pem | der | pkcs12 }            \n                                                                                \n                                   (default: 'pem')                             \n\n-i|--id \u003cid\u003e                       ID of the object to create or operate on.    \n                                   Run './sc.sh --list object' to list all      \n                                   available objects.                           \n\n--key-type \u003ctype\u003e                  Type and length of the key to create. Run    \n                                   './sc.sh --list algorithm' to get a list of  \n                                   algorithms supported by the token. Depending \n                                   on the token type this value must follow one \n                                   of the following forms (without ''):         \n                                                                                \n                                   ***** OpenSC PKCS#11 ('-T opensc-p11') ***** \n                                   ***** SmartCard-HSM / Nitrokey HSM 2 ('-T    \n                                   schsm') *****                                \n                                   '\u003ctype\u003e:\u003clength\u003e', e.g. 'rsa:4096' or        \n                                   'EC:prime256v1'                              \n                                                                                \n                                   ***** OpenSC PKCS#15 ('-T opensc-p15') ***** \n                                   '\u003ctype\u003e/\u003clength\u003e', e.g. 'rsa/2048' or        \n                                   'ec/prime256v1'                              \n                                                                                \n                                   ***** Yubico YubiKey PIV ('-T yubico') ***** \n                                   '\u003cTYPE\u003e\u003clength\u003e', e.g. 'RSA2048' or          \n                                   'ECCP384'. Only the following values are     \n                                   allowed:                                     \n                                                                                \n                                   Private Key                                  \n                                   \u003ctype\u003e = { RSA2048 | RSA1024 | ECCP256 |     \n                                   ECCP384 }                                    \n                                                                                \n                                   Management Key                               \n                                   \u003ctype\u003e = { AES256 | AES192 | AES128 | TDES } \n                                                                                \n                                   (default: 'rsa:2048')                        \n\n-l|--label \u003clabel\u003e                 Label (name) of the object to operate on (or \n                                   the token label when '--initialize' is       \n                                   used). Run './sc.sh --list object' to list   \n                                   all available objects.                       \n\n-n|--new-pin|--new-puk|            New user PIN, PUK, or security officer PIN.  \n--new-so-pin \u003cval\u003e                 Use this option only in case you change an   \n                                   Use this option only in case you change an   \n                                   existing value. With '--initialize' or       \n                                   '--store-pin' please use other options, e.g. \n                                   '-p|--pin \u003cpin\u003e'. See also (1) and (2).      \n\n--p15-aid \u003cid\u003e                     Set the hexadecimal application id (AID) of  \n                                   the PKCS#15 application to bind to. Run      \n                                   './sc.sh -T opensc-p15 --list                \n                                   p15-application' to list all available       \n                                   PKCS#15 applications.                        \n\n--p15-auth-id \u003cid\u003e                 Specify the hexadecimal auth id of the       \n                                   PIN/PUK pair to use/create. Run './sc.sh -T  \n                                   opensc-p15 --list p15-pin' to list all       \n                                   available PKCS#15 PINs.                      \n\n--piv-id \u003cid\u003e                      PIV object identifier (BER-TLV Tag)          \n                                                                                \n                                   \u003cid\u003e = { 5FC107 | 5FC102 | 5FC105 | 5FC103 | \n                                   5FC106 | 5FC108 | 5FC101 | 5FC10A | 5FC10B | \n                                   5FC109 | 7E | 5FC10C | 5FC10D | 5FC10E |     \n                                   5FC10F | 5FC110 | 5FC111 | 5FC112 | 5FC113 | \n                                   5FC114 | 5FC115 | 5FC116 | 5FC117 | 5FC118 | \n                                   5FC119 | 5FC11A | 5FC11B | 5FC11C | 5FC11D | \n                                   5FC11E | 5FC11F | 5FC120 | 5FC121 | 7F61 |   \n                                   5FC122 | 5FC123 }                            \n                                                                                \n                                   See also:                                    \n                                     NIST SP 800-73-4 (Section 4.3 \"Object      \n                                   Identifiers\")                                \n                                       https://doi.org/10.6028/NIST.SP.800-73-4 \n                                     Yubico                                     \n                                                                                \n                                   https://developers.yubico.com/yubico-piv-tool\n                                   /Actions/read_write_objects.html             \n\n--piv-slot \u003cid\u003e                    PIV slot (key reference value)               \n                                                                                \n                                   \u003cid\u003e = { 04 | 9A | 9C | 9D | 9E | 82 | 83 |  \n                                   84 | 85 | 86 | 87 | 88 | 89 | 8A | 8B | 8C | \n                                   8D | 8E | 8F | 90 | 91 | 92 | 93 | 94 | 95 | \n                                   F9 }                                         \n                                                                                \n                                   See also:                                    \n                                     NIST SP 800-73-4 (Section 5.1 \"Key         \n                                   References\")                                 \n                                       https://doi.org/10.6028/NIST.SP.800-73-4 \n                                     Yubico                                     \n                                                                                \n                                   https://developers.yubico.com/PIV/Introductio\n                                   n/Certificate_slots.html                     \n\n--password \u003cpwd\u003e                   Password for exporting/importing             \n                                   password-protected files. See also (1) and   \n                                   (2).                                         \n\n-p|--pin \u003cpin\u003e                     (Current or initial) user PIN. See also (1)  \n                                   and (2).                                     \n                                                                                \n                                   ***** OpenSC PKCS#15 ('-T opensc-p15') ***** \n                                   Use '--p15-auth-id \u003cid\u003e' to specify the      \n                                   hexadecimal auth id of PIN/PUK pair to       \n                                   use/create.                                  \n\n-P|--puk \u003cpuk\u003e                     (Current or initial) user PUK. See also (1)  \n                                   and (2).                                     \n                                                                                \n                                   ***** OpenSC PKCS#15 ('-T opensc-p15') ***** \n                                   Use '--p15-auth-id \u003cid\u003e' to specify the      \n                                   hexadecimal auth id of PIN/PUK pair to       \n                                   use/create.                                  \n\n-r|--reader \u003cid\u003e                   Specify slot/reader to use by its decimal    \n                                   ID/index \u003cid\u003e. Run './sc.sh --list reader'   \n                                   to list all available slots/readers.         \n\n--serial \u003cserial no\u003e               ***** Yubico YubiKey PIV ('-T yubico') ***** \n                                   Specify token to use by its serial number.   \n                                   Run './sc.sh --list reader' to list all      \n                                   available tokens.                            \n\n-s|--so-pin \u003cso pin\u003e               (Current or initial) security officer PIN    \n                                   (SO-PIN). See also (1) and (2).              \n                                                                                \n                                   ***** OpenSC PKCS#15 ('-T opensc-p15') ***** \n                                   Use '--p15-auth-id \u003cid\u003e' to specify the      \n                                   hexadecimal auth id of PIN/PUK pair to       \n                                   use/create.                                  \n\n-S|--so-puk \u003cso puk\u003e               (Current or initial) security officer PUK    \n                                   (SO-PUK). See also (1) and (2).              \n                                                                                \n                                   ***** OpenSC PKCS#15 ('-T opensc-p15') ***** \n                                   Use '--p15-auth-id \u003cid\u003e' to specify the      \n                                   hexadecimal auth id of PIN/PUK pair to       \n                                   use/create.                                  \n\n-t|--type \u003ctype\u003e                   Specify object type. Some types are only     \n                                   available with certain token types.          \n                                                                                \n                                              cert  :  Certificate              \n                                              data  :  Data Object              \n                                            object  :  (All) Objects            \n                                           privkey  :  Private Key              \n                                            pubkey  :  Public Key               \n                                           secrkey  :  Secret Key               \n                                             chain  :  Certificate Chain        \n                                            sshkey  :  SSH Key                  \n                                    sshkey-rfc4716  :  SSH Key (RFC4716)        \n                                         algorithm  :  Supported                \n                                                       Mechanisms               \n                                                       (algorithms, key         \n                                                       lengths, ...)            \n                                              info  :  General Information      \n                                            reader  :  Available                \n                                                       Reader/Slots             \n                                   p15-application  :  PKCS#15 Application      \n                                           p15-pin  :  PKCS#15 PIN              \n\n________________________________ OpenSC PKCS#15 ________________________________\n\n--opensc-p15-profile \u003cprofile\u003e     Specify OpenSC PKCS#15 profile to load       \n                                   during initialization in the form of         \n                                   '\u003cprofile\u003e[+\u003coption\u003e]...', e.g.              \n                                   'pkcs15+onepin' in case your token only      \n                                   supports one user PIN/PUK pair but no        \n                                   separate SO-PIN/SO-PUK.                      \n                                                                                \n                                   For more information please have a look at   \n                                   the manpage by running 'man pkcs15-init',    \n                                   parameter \"--profile\".                       \n                                                                                \n                                   (default: 'pkcs15')                          \n\n________________________ SmartCard-HSM / Nitrokey HSM 2 ________________________\n\n--schsm-dkek-shares \u003cint\u003e              Specify number of DKEK shares (files)    \n                                       that are necessary to recreate the       \n                                       Device Key Encryption Key (DKEK). All    \n                                       DKEK shares are needed to backup/restore \n                                       the keys. Usually you set \u003cint\u003e to '1'.  \n                                       Leave this parameter out or set \u003cint\u003e to \n                                       '' to disable DKEK creation and the key  \n                                       backup/restore feature. Set \u003cint\u003e to '0' \n                                       to create a random DKEK meaning that     \n                                       keys backed up with this DKEK can only   \n                                       be restored in the same HSM. Please do   \n                                       not confuse this with DKEK password      \n                                       n-of-m threshold scheme. Use './sc.sh    \n                                       --schsm-dkek-share-create \u003cfile\u003e' to     \n                                       create the DKEK share(s).                \n                                                                                \n                                       (default: '')                            \n\n--schsm-key-reference \u003cid\u003e             Specify key (identifier) to              \n                                       backup/restore. Run 'pkcs15-tool --dump' \n                                       to show available keys to backup or free \n                                       reference ids to use for restore (in the \n                                       command's output the relevant value is   \n                                       the 'Key ref' field).                    \n                                                                                \n                                       (default: '1')                           \n\n--schsm-pwd-shares-threshold \u003cint\u003e     Threshold (minimum) number of password   \n                                       shares required for deciphering the DKEK \n                                       share                                    \n                                                                                \n                                       (default: '')                            \n\n--schsm-pwd-shares-total \u003cint\u003e         Total number of password shares used to  \n                                       encipher the DKEK share                  \n                                                                                \n                                       (default: '')                            \n\n______________________________ Yubico YubiKey PIV ______________________________\n\n--yubico-management-key \u003ckey\u003e         Specify current management key in hex     \n                                      form (without '0x'). Length depends on    \n                                      '--key-type \u003ctype\u003e', e.g. 32 bytes for    \n                                      AES256. See also (1) and (2).             \n\n--yubico-new-management-key \u003ckey\u003e     Specify new management key in hex form    \n                                      (without '0x'). Length depends on         \n                                      '--key-type \u003ctype\u003e', e.g. 32 bytes for    \n                                      AES256. See also (1) and (2).             \n\n--yubico-pin-policy \u003cpol\u003e             PIN policy, defines if or how often a     \n                                      user must confirm key-related operations  \n                                      by entering the user PIN. See also:       \n                                      https://docs.yubico.com/yesdk/users-manual\n                                      /application-piv/pin-touch-policies.html  \n                                                                                \n                                      Possible values are:                      \n                                                                                \n                                      default  :  Default                       \n                                       always  :  Always                        \n                                         once  :  Once (per session)            \n                                        never  :  Never                         \n                                                                                \n                                      (default: 'default')                      \n\n--yubico-touch-policy \u003cpol\u003e           Touch policy, defines if or how often a   \n                                      user must confirm key-related operations  \n                                      by pushing YubiKey's button. See also:    \n                                      https://docs.yubico.com/yesdk/users-manual\n                                      /application-piv/pin-touch-policies.html  \n                                                                                \n                                      Possible values are:                      \n                                                                                \n                                      default  :  Default                       \n                                       always  :  Always                        \n                                       cached  :  Cached (A touch is not        \n                                                  needed if the YubiKey had     \n                                                  been touched within the       \n                                                  last 15 seconds.)             \n                                        never  :  Never                         \n                                                                                \n                                      (default: 'default')                      \n\n================================================================================\n================================     NOTES     =================================\n================================================================================\n\n_____________________________________ (1) ______________________________________\n\nMinimum/Maximum length and allowed characters depend on the token type and model. For more information please also consult your token's data sheet or manual.\n\n***** OpenSC PKCS#11 ('-T opensc-p11') *****\n***** OpenSC PKCS#15 ('-T opensc-p15') *****\nPIN:    6 - 8 characters, digits (0-9) only\nPUK:    Exactly 8 characters, digits only\nSO-PIN: 6 - 8 characters, digits only\n\n\n***** OpenSC PKCS#15 ('-T opensc-p15') *****\nPUK:    8 - 16 (*) characters, digits only\nSO-PUK: 8 - 16 (*) characters, digits only\n\n(*) To conform with 'FIPS-201 (PIV Card)' standard it must be exactly 8 characters long.\n\n\n***** SmartCard-HSM / Nitrokey HSM 2 ('-T schsm') *****\nPIN:    6 - 15 bytes, ASCII characters only\nPUK:    (not available)\nSO-PIN: Exactly 16 hexadecimal (0-9 a-f) characters\nPassword (DKEK Share): \u003e= 10 characters, any\n\nFirmware versions before 1.0 have some restrictions, e.g.\n  - Device has to be reinitialized to reset the user PIN,\n    losing all certs/data/keys.\n  - Security Officer PIN (SO-PIN) can only be set once(!)\n    during first initialization.\n\nSee also:\n  https://github.com/OpenSC/OpenSC/wiki/SmartCardHSM#using-pkcs11-tool\n  https://raymii.org/s/articles/Get_Started_With_The_Nitrokey_HSM.html\n\n\n***** Yubico YubiKey PIV ('-T yubico') *****\nPIN:    6 - 8 bytes, ASCII characters only\nPUK:    6 - 8 bytes, any value (ASCII characters only recommended)\nManagement Key:\n        Length depends on the key type ('--key-type \u003ctype\u003e').\n        Exactly 32 (AES128), 48 (AES192, TDES), 64 (AES256)\n        characters, hexadecimal (0-9 a-f) only.\n\nSee also:\n  https://docs.yubico.com/yesdk/users-manual/application-piv/pin-puk-mgmt-key.html\n\n\n***** FIPS 201 (PIV Card) *****\nPIN:    6 - 8 bytes, only ASCII numbers 0-9 ('0x30' - '0x39')\nPUK:    8 bytes, any binary value ('0x00' - '0xFF')\n\nSee also:\n  NIST SP 800-73-4 (Section \"2.4.3 Authentication of an Individual\")\n  https://doi.org/10.6028/NIST.SP.800-73-4\n\n_____________________________________ (2) ______________________________________\n\nIt is highly recommended to pass credentials only via environment variables. To do so, just set this value to 'env:\u003cVAR\u003e' (without '' \u003c\u003e) where \u003cVAR\u003e is your environment variable's name.\n\nPlease note that passing credentials in clear-text form can be highly insecure as any other user/process could display the command line of this application by using system utilities like 'ps'.\n\nExample: You would like to pass the password '123456'.\n\n  Via an environment variable (preferred)\n    \u003e export mypwd=\"123456\"\n    \u003e ... \"env:mypwd\"\n\n  Directly, in clear-text form (NOT recommended)\n    \u003e ... \"123456\"\n```\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- ROADMAP --\u003e\n## Roadmap\n\nSee the [open issues](https://github.com/fkemser/SCwrapper/issues) for a full list of proposed features (and known issues).\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- CONTRIBUTING --\u003e\n## Contributing\n\nContributions are what make the open source community such an amazing place to learn, inspire, and create. Any contributions you make are **greatly appreciated**.\n\nIf you have a suggestion that would make this better, please fork the repo and create a pull request. You can also simply open an issue with the tag \"enhancement\".\nDon't forget to give the project a star! Thanks again!\n\n1. Fork the Project\n2. Create your Feature Branch (`git checkout -b feature/AmazingFeature`)\n3. Commit your Changes (`git commit -m 'Add some AmazingFeature'`)\n4. Push to the Branch (`git push origin feature/AmazingFeature`)\n5. Open a Pull Request\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- LICENSE --\u003e\n## License\n\nDistributed under the **GNU General Public License v3.0 (or later)**. See [`LICENSE`][license-url] for more information.  \n\n\u003e :warning: The license above does not apply to the files and folders within the library directory `/lib`. Please have a look at the `LICENSE` file located in the root directory of each library to get more information.\n\n\u003e :warning: The license above may not apply to some files within the TeX letter directory `/tex`. Please have a look at the `SPDX-FileCopyrightText` and `SPDX-License-Identifier` headers in each file to get more information.\n\n\u003e :warning: The license above does not apply to the sample logo file `/tex/logo.png`. For more information please have a look at [Logoipsum's terms of license](https://logoipsum.com/license).\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- CONTACT --\u003e\n## Contact\n\nProject Link: [https://github.com/fkemser/SCwrapper](https://github.com/fkemser/SCwrapper)\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- ACKNOWLEDGMENTS --\u003e\n## Acknowledgments\n\n###\n* [Dialog](https://invisible-island.net/dialog/dialog.html)\n* [GnuTLS](https://www.gnutls.org/)\n* [OpenSC](https://github.com/OpenSC/OpenSC)\n* [OpenSC (PKCS#11 module)](https://github.com/OpenSC/libp11)\n* [OpenSSL](https://www.openssl.org/)\n* [PCSClite](https://pcsclite.apdu.fr/)\n* [USB PC/SC CCID driver](https://ccid.apdu.fr/)\n* [Yubico PIV tool (PKCS#11 module)](https://developers.yubico.com/yubico-piv-tool/)\n* [YubiKey Manager](https://developers.yubico.com/yubikey-manager/)\n\n###\n* [The LaTeX Project](https://www.latex-project.org/)\n* [TeX Live - TeX Users Group (tug.org)](https://www.tug.org/texlive/)\n* [LuaTeX](https://www.luatex.org/)\n\n###\n* [environ (CTAN)](https://www.ctan.org/pkg/environ)\n* [microtype (CTAN)](https://www.ctan.org/pkg/microtype)\n* [pgf (CTAN)](https://www.ctan.org/pkg/pgf)\n* [tcolorbox (CTAN)](https://www.ctan.org/pkg/tcolorbox)\n* [tikzfill (CTAN)](https://www.ctan.org/pkg/tikzfill)\n* [trimspaces (CTAN)](https://www.ctan.org/pkg/trimspaces)\n\n###\n* [othneildrew/Best-README-Template](https://github.com/othneildrew/Best-README-Template)\n* [Ileriayo/markdown-badges](https://github.com/Ileriayo/markdown-badges)\n\n\u003cp align=\"right\"\u003e(\u003ca href=\"#readme-top\"\u003eback to top\u003c/a\u003e)\u003c/p\u003e\n\n\n\n\u003c!-- MARKDOWN LINKS \u0026 IMAGES --\u003e\n\u003c!-- https://www.markdownguide.org/basic-syntax/#reference-style-links --\u003e\n[contributors-shield]: https://img.shields.io/github/contributors/fkemser/SCwrapper.svg?style=for-the-badge\n[contributors-url]: https://github.com/fkemser/SCwrapper/graphs/contributors\n[forks-shield]: https://img.shields.io/github/forks/fkemser/SCwrapper.svg?style=for-the-badge\n[forks-url]: https://github.com/fkemser/SCwrapper/network/members\n[stars-shield]: https://img.shields.io/github/stars/fkemser/SCwrapper.svg?style=for-the-badge\n[stars-url]: https://github.com/fkemser/SCwrapper/stargazers\n[issues-shield]: https://img.shields.io/github/issues/fkemser/SCwrapper.svg?style=for-the-badge\n[issues-url]: https://github.com/fkemser/SCwrapper/issues\n[license-shield]: https://img.shields.io/github/license/fkemser/SCwrapper.svg?style=for-the-badge\n[license-url]: https://github.com/fkemser/SCwrapper/blob/main/LICENSE\n[linkedin-shield]: https://img.shields.io/badge/-LinkedIn-black.svg?style=for-the-badge\u0026logo=linkedin\u0026colorB=555\n[linkedin-url]: https://linkedin.com/in/linkedin_username\n\n[SHlib-url]: https://github.com/fkemser/SHlib\n[SHtemplateLIB-url]: https://github.com/fkemser/SHtemplateLIB\n\n[iso639-1-url]: https://en.wikipedia.org/wiki/List_of_ISO_639-1_codes\n\n[LaTeX-shield]: https://img.shields.io/badge/latex-%23008080.svg?style=for-the-badge\u0026logo=latex\u0026logoColor=white\n[LaTeX-url]: https://www.latex-project.org/\n[Shell Script-shield]: https://img.shields.io/badge/shell_script-%23121011.svg?style=for-the-badge\u0026logo=gnu-bash\u0026logoColor=white\n[Shell Script-url]: https://pubs.opengroup.org/onlinepubs/9699919799/\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffkemser%2Fscwrapper","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffkemser%2Fscwrapper","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffkemser%2Fscwrapper/lists"}